Two job titles, one craft. A SOC analyst and an MDR analyst both spend their day triaging alerts, investigating suspicious activity, and turning what they learn into better detections. The difference is who they do it for: an in-house SOC defends one organization, while an MDR (Managed Detection and Response) analyst defends dozens or hundreds of customer environments from the provider side - at companies like Arctic Wolf, Expel, ReliaQuest, Sophos, or CrowdStrike's Falcon Complete team. In 2026 that distinction matters more than most candidates realize, because MDR providers are where a large share of the actual analyst hiring happens. This guide covers how the two seats differ day to day, what each does to your career trajectory, how pay compares, and how to move between them.
What each job actually is
An in-house SOC analyst works inside one company's security team. You learn one environment deeply: its network layout, its business applications, its normal. Over months you develop the context that makes a great investigator - you know that the finance team runs a weird legacy tool that always trips the EDR, and that a login from a particular subnet at 3 AM is genuinely strange. The alert queue is yours, but so is everything around it: tuning, stakeholder questions, audit evidence, and the occasional all-hands incident.
An MDR analyst works for a security vendor that sells detection and response as a service. Your queue spans many customers at once. You will see more genuine incidents in a quarter than many in-house analysts see in a year, because you are watching a much larger attack surface. The trade: you rarely get deep context on any single customer. Investigations lean harder on telemetry, playbooks, and the provider's own detection content, and customer communication is part of the deliverable - your incident write-up goes to someone who pays for it.
The day-to-day differences
| In-house SOC | MDR provider | |
|---|---|---|
| Scope | One environment, deep | Many environments, broad |
| Incident volume | Lower, higher context per incident | High - real intrusions weekly, not yearly |
| Tooling | Whatever your employer bought | Usually the vendor's own stack, at scale |
| Context | You know what normal looks like | You infer normal from telemetry fast |
| Writing | Internal tickets and post-incident reports | Customer-facing findings - quality is the product |
| Shift work | Common in 24/7 SOCs | Near-universal - follow-the-sun or rotating shifts |
| Hiring volume | A few seats per company | Cohorts - providers hire and train at volume |
Tooling: breadth versus depth
In-house, you go deep on one stack: the SIEM your company runs, its EDR, its cloud provider's audit logs. That depth is valuable - "can actually query Splunk under pressure" is a hireable skill on its own. At an MDR provider you typically live inside the vendor's own platform, but you see how attacks look across Windows-heavy enterprises, cloud-native startups, healthcare networks, and everything in between. Breadth of attack exposure is the MDR seat's superpower; breadth of tooling is often narrower than people expect, because the provider standardizes on its own stack.
The shift-work honesty section
Both paths involve shift work early on, and MDR more so: detection-as-a-service is a 24/7 promise, so nights, weekends, and rotating schedules are structural, not temporary. Shift differentials typically add 10-15% on top of base pay, which partially compensates. If your life cannot absorb night shifts, say so before you accept either seat - and know that the escape route in both worlds is the same: seniority, then a move into detection engineering, threat hunting, or incident response roles that run on business hours.
Career ladders: where each seat leads
The in-house ladder is the classic one: Tier 1 triage, Tier 2 investigation, then Tier 3 hunting and detection engineering, with exits into incident response, threat hunting, or security engineering. Your promotion case is built on knowing the environment better than anyone.
The MDR ladder moves faster at the bottom because the incident reps come faster. A year of MDR triage can teach you more real intrusion patterns than several years of a quiet internal queue. Senior MDR analysts move into the provider's detection engineering or threat research teams, into team-lead and SOC management tracks, or - very commonly - out to an in-house team that values someone who has seen hundreds of real incidents. The reverse move works too: in-house analysts join MDR vendors to escape a stagnant environment and multiply their exposure.
What the two paths pay
At the analyst tier the bands are broadly similar, because the work is similar. US SOC analyst roles band roughly $58,000 to $92,000 across the tiers in our benchmark data, with shift differentials on top for 24/7 coverage. MDR providers compete in the same range for the same people; where they differ is volume and progression speed rather than the starting number. The full country-by-country breakdown is in our SOC analyst salary guide →. One honest caveat: neither seat is where security pay peaks. The money move in both worlds is the step up into detection engineering or security engineering, where US bands run substantially higher.
Who is actually hiring
On our board right now the MDR-titled inventory comes from names like Palo Alto Networks (Unit 42 MDR), Sophos, SentinelOne, Trend Micro, Varonis, Sygnia, Vectra, and Cato Networks, alongside the dedicated MDR firms - Arctic Wolf, Expel, ReliaQuest, Huntress. Browse the live MDR jobs → and SOC analyst jobs → side by side and you will notice the MDR listings skew toward providers hiring several analysts at once - which is exactly why MDR is one of the widest genuine entry doors into security operations. For the broader detection career track, the detection engineering hub → is the next page to bookmark.
How to choose (and how to switch)
- Pick MDR if you are breaking in or early-career and want maximum incident reps fast, you can handle shift schedules, and you want to be hired by a company whose entire business is the thing you are learning. MDR providers train because they must - their margins depend on making junior analysts effective quickly.
- Pick in-house if you want depth over breadth, care about learning the full life of a security program (tuning, stakeholders, audits, engineering projects), or you are targeting a specific industry like finance or healthcare where environment context compounds into specialist value.
- Switching MDR to in-house: lead your resume with incident volume and variety - "investigated and contained intrusions across N customer environments" is a stronger claim than any tool list. Expect interviewers to probe whether you can operate without a playbook.
- Switching in-house to MDR: lead with investigation quality and writing. Providers screen hard for clear customer-facing communication, because your report is what the customer is paying for.
Neither door is the wrong one. The skills transfer almost completely, employers on both sides hire from the other, and the fundamentals are identical: telemetry fluency, one SIEM known properly, and investigation write-ups a stranger can follow. If you are starting from zero, the full roadmap - skills, certifications in order, proof-of-work - is in our how to become a SOC analyst guide →.
Live SOC, MDR & detection roles
Related guides
Security+ vs CySA+: Which CompTIA Cert First?
The practical order for the two analyst-track CompTIA certifications - what each exam tests, who can skip stra…
8 min read
OSCP vs CEH in 2026: The Honest Comparison
OSCP is the hands-on standard practitioners respect; CEH is the checkbox HR filters and DoD contracts look for…
9 min read
How to Use ChatGPT (and Other AI Assistants) to Find a Cybersecurity Job in 2026
The practical AI job-search workflow: copy-paste prompt patterns for role discovery, salary research, resume t…
9 min read